4.7
CVSSv3

CVE-2018-1261

Published: 11/05/2018 Updated: 12/08/2021
CVSS v2 Base Score: 4 | Impact Score: 4.9 | Exploitability Score: 4.9
CVSS v3 Base Score: 4.7 | Impact Score: 3.6 | Exploitability Score: 1
VMScore: 356
Vector: AV:N/AC:H/Au:N/C:N/I:P/A:P

Vulnerability Summary

Spring-integration-zip versions before 1.0.1 exposes an arbitrary file write vulnerability, which can be achieved using a specially crafted zip archive (affects other archives as well, bzip2, tar, xz, war, cpio, 7z) that holds path traversal filenames. So when the filename gets concatenated to the target extraction directory, the final path ends up outside of the target folder.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

vmware spring integration zip

Github Repositories

notes

hacked by haby0 2022年 <article month=04 day=07 title="编译原理资料"/> <article month=01 day=29 title="CodeQL Java CSV flow模型"/> 2021年 <article month=12 day=15 title="Web漏扫扫描Log4j RCE漏洞"/> <article month=11 day=18 title="CodeQL Variable Study"/> &